CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,094 vulnerabilities with CWE-400
CVE-2026-41708 HIGH
Spring Cloud Sleuth instrumentation of Spring TX DoS vulnerability
CVSS 7.5
CVE-2026-5079 HIGH
multer vulnerable to Denial of Service via deeply nested field names
CVSS 7.5
CVE-2026-50011 HIGH
Netty has unbounded pre-allocation in RedisArrayAggregator from RESP array length
CVSS 7.5
CVE-2026-48043 MEDIUM
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
CVSS 5.3
CVE-2026-47244 MEDIUM
Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced
CVSS 5.3
CVE-2026-50645 HIGH
Apache CXF: No restriction on attachment headers per message
CVSS 7.5
CVE-2026-45169 HIGH
Idira Privileged Access Manager (PAM) Self-Hosted Vault: Denial of Service due to Unexpected Input Processing
CVE-2026-44892 HIGH
Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size
CVSS 7.5
CVE-2026-44890 HIGH
Netty has Unbounded Direct Memory Consumption in its RedisDecoder
CVSS 7.5
CVE-2026-44250 HIGH
Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays
CVSS 7.5
CVE-2026-45802 MEDIUM
FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service
CVE-2026-44496 HIGH
Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
CVSS 7.5
CVE-2026-5497 HIGH
Unbounded Frame Count in video/jpeg Base64 Data URL Processing Leads to OOM DoS in vllm-project/vllm
CVSS 7.5
CVE-2026-47734 MEDIUM
Dulwich has unbounded memory allocation in receive-pack from crafted thin packs
CVSS 5.7
CVE-2026-46689 HIGH
Kanidm: Unauthenticated process abort via SCIM filter stack exhaustion
CVE-2026-46679 HIGH
libp2p: Memory DoS via subscription flood of unique topics
CVSS 7.5
CVE-2026-46522 HIGH
ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion
CVSS 7.5
CVE-2026-45783 HIGH
libp2p: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT server nodes
CVSS 7.5
CVE-2026-45664 MEDIUM
ImageMagick: Policy Bypass in MNG coder could
CVSS 5.3
CVE-2026-45031 MEDIUM
ImageMagick: Policy Bypass in PSD decoder
CVSS 5.3
CVE-2026-10143 HIGH
kafka-python prior to 2.3.2 DoS via SCRAM Iteration Count in scram.py
CVSS 7.5
CVE-2026-41721 MEDIUM
Spring Data Commons Denial of Service via Data Binding
CVSS 5.9
CVE-2026-41711 MEDIUM
Spring Data Commons - Potential Denial of Service Through Crafted Sort Parameters
CVSS 5.9
CVE-2026-41695 HIGH
Denial of Service in Spring Data Commons Property Path Resolution
CVSS 7.5
CVE-2026-40988 HIGH
Unbounded DEFLATE Inflation in SAML 2.0 Service Provider
CVSS 7.5
Details
Vulnerabilities 3,094
Exploit Likelihood High